Unlock Full Resume Report

New offer - be the first one to apply!

September 21, 2026

Lead AI Security Engineer

Senior • Remote

Warsaw, MA, Poland

Quick Facts

  • Role: Lead AI Security Engineer

Description

Lead security for software across the full development lifecycle by embedding secure-by-design and shift-left AppSec practices. Operate and tune application security tooling and pipelines in CI/CD, perform threat modeling and secure design/code reviews, and drive remediation with engineering. Apply AI to accelerate AppSec work and to secure AI- and LLM-powered applications using guardrails, evaluation workflows, and secure AI controls.

Responsibilities

  • Embed security into the full SDLC and drive secure-by-design practices across engineering teams
  • Facilitate threat modeling, architecture security reviews, and design reviews for applications, services, and APIs
  • Conduct secure code reviews (manual and AI-assisted) and advise developers on secure coding patterns and remediation
  • Implement, configure, tune, and operate SAST, DAST, IAST, SCA, secrets scanning, and IaC scanning integrated into CI/CD pipelines
  • Triage and validate security findings, reduce false positives, and partner with development teams to track issues to remediation
  • Define and maintain security gates and policies in CI/CD that balance risk reduction with developer velocity
  • Secure the software supply chain (dependency/open-source risk management, SBOM generation, artifact integrity and signing, build hardening)
  • Support application penetration testing and validate fixes
  • Drive security for secrets management, secure configuration, API security, container/image security, and microservice security
  • Establish a security champions program and deliver secure-coding training, guidelines, and reusable patterns
  • Define and maintain application security standards/baselines and policy-as-code; contribute to vulnerability management and risk acceptance
  • Build and maintain AI-assisted automations/agentic workflows for triage, deduplication, prioritization, false-positive reduction, code review with remediation guidance, threat modeling support, enrichment/root-cause analysis, remediation-PR drafting, and compliance evidence collection
  • Build and integrate AI agents and LLM-backed automations into SDLC/CI/CD via function calling, REST, and webhooks
  • Develop reusable prompts and structured prompting patterns; tune for accuracy, signal quality, and safe behavior
  • Implement retrieval over internal codebase/standards/remediation guidance (e.g., RAG)
  • Add evaluation and human-in-the-loop checkpoints (verification, guardrails, approval gates)
  • Implement AI usage security/privacy controls (least-privilege agent access, secrets handling, prompt-injection resistance, auditability)
  • Design controls for AI/LLM app features (input/output validation, jailbreak defenses, tool/function-call authorization, rate limiting, model/data access governance aligned to OWASP Top 10 for LLM Applications)
  • Define and enforce AI adoption guardrails (prompt security, model/tool access control, output handling, data protection, auditability, and human-in-the-loop)

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or equivalent practical experience
  • Hands-on application security experience across the software development lifecycle
  • Strong understanding of common application vulnerability classes and mitigations (OWASP Top 10) and secure coding principles
  • Practical experience with SAST, DAST, SCA, and secrets scanning; integrating into CI/CD
  • Working knowledge of at least one programming language (e.g., Python, Java, C#, JavaScript/TypeScript, Go)
  • Experience with threat modeling and secure design review methodologies
  • Understanding of DevOps/DevSecOps, CI/CD pipelines, and secure-by-design principles
  • Familiarity with cloud application security across at least one major cloud platform (Azure/AWS/GCP)
  • Experience working across several production projects/engineering teams
  • Ability to collaborate closely and influence without owning the codebase
  • Ability to follow, maintain, and improve defined security processes
  • Practical understanding of AI-assisted productivity/automation (agents, LLM tool integration, prompt engineering, AI runbooks/scripts/queries/docs, secure AI usage with sensitive data awareness)
  • Good communication skills for technical and non-technical stakeholders

Benefits

  • Stable pay and participation in the Employee Stock Purchase Plan with a 15% discount
  • Benefits package: health insurance, multisport, shopping vouchers
  • Referral bonuses up to $2,000
  • Hybrid-by-design with opportunity to work remotely within Poland
  • Chance to work abroad for up to 60 days annually and business-driven relocation opportunities
  • Career development programs, mentoring, soft skills and well-being programs
  • Certification support (e.g., Anthropic, Gemini, GCP, Azure, AWS) and English classes
  • Corporate events and well-being initiatives
  • Office amenities (entertainment/relaxation zones, table tennis/football, free snacks/coffee)
  • Contractor work possible (B2B terms agreed individually)

Similar jobs you might like